Book a demo

1. About this Privacy Policy

Ralle Pty Ltd ACN 694 562 920 (Ralle, we, us) provides engagement infrastructure for membership organisations. Our platform issues digital membership passes to mobile wallets and connects the systems that membership organisations already use, including membership records, point of sale, payments and communications. This website, ralle.co, is owned and operated by Ralle.

This Privacy Policy explains how we handle personal information. It applies to our websites, our platform and our dealings with customers, partners and prospective customers.

We are committed to complying with the Australian Privacy Act 1988 and the Australian Privacy Principles, the Spam Act 2003, and, where they apply to us, the UK General Data Protection Regulation, the Data Protection Act 2018 and the EU General Data Protection Regulation.

In this Policy, personal information and personal data have the meanings given to them under the applicable law. Both terms refer to information about an identified or identifiable individual.

2. When we are a controller and when we are a processor

Ralle handles personal information in two different capacities, and different parts of this Policy apply to each.

Ralle as a controller

We act as a controller, and this Privacy Policy applies in full, where we decide how and why personal information is used. This covers visitors to our websites, representatives of our current and prospective customers and partners, people who contact us, and recipients of our marketing communications.

Ralle as a processor

We act as a processor where we handle personal information about the members, participants, supporters or patrons of an organisation that uses our platform. In those cases the organisation is the controller. It decides what information is collected and why, and it is responsible for providing its own privacy notice to those individuals.

Our handling of that information is governed by our agreement with that organisation, including its data processing terms, rather than by this Privacy Policy. If you are a member of a club, association, charity or venue that uses Ralle and you want to know how your information is used, contact that organisation in the first instance. We will assist them in responding to you.

3. Application of this Privacy Policy

By using a Ralle website (Website) or our platform, or entering into an agreement with us in relation to them (collectively the Services), you acknowledge that we collect, use, disclose and handle your personal information in accordance with this Privacy Policy.

This Privacy Policy is in addition to any other terms and conditions applicable to the Services. Specific privacy terms contained in any documents made available by us should be read together with this Privacy Policy. Where there is any inconsistency between this Privacy Policy and the data processing terms of a customer agreement, those data processing terms prevail in respect of the information they cover.

4. Information we collect

Where we act as a controller, the information we collect includes:

  • information about your use of our Websites, including browser statistics, IP address, how long you spend on our Websites, the pages you visit and the date and time of your visits;
  • information you provide when registering with our Websites or using our products or services, such as your name, phone number, email address and postal address;
  • information you provide when subscribing to our Websites or other Services, such as your name, contact information and employer details, where you are a representative of a current or prospective customer or partner;
  • information you provide when you communicate with us by email, phone, through our Websites, or in person; and
  • your marketing preferences, including whether you have consented to receiving direct marketing.

We do not ordinarily record phone calls or meetings. If we do, we will tell you at the start and give you the opportunity to opt out.

We collect most of this information directly from you. We may also collect it from our customers and partners, from publicly available sources, and from marketing opt-in lists where the provider confirms an appropriate lawful basis for sharing it with us.

If you provide us with personal information about another individual, you must have that person’s authority to do so. By providing it, you confirm that you have.

We do not seek to collect sensitive information or special category data in our capacity as a controller. Where we hold such information as a processor, it is collected on the instructions of the relevant customer under our agreement with them.

Our Websites are not directed at children, and we do not knowingly collect personal information from children through them.

5. How we use information, and our lawful basis

Where we act as a controller, we use personal information for the purposes below. The lawful basis column applies where the UK GDPR or EU GDPR governs the processing. Where Australian privacy law applies, we handle the information for the purpose it was collected and for related purposes you would reasonably expect.

Where we rely on legitimate interests, we have considered whether those interests are outweighed by your interests and rights. You can ask us for more information about that assessment using the contact details in section 14.

6. Disclosure of information

We may disclose personal information to:

  • your authorised representatives and agents;
  • our service providers, who process information on our behalf and under our instructions;
  • our customers and partners, where the disclosure forms part of a product or service we provide to them;
  • professional advisers, including lawyers, accountants and insurers;
  • an organisation that acquires all or part of our assets or business, or is considering doing so;
  • government agencies, regulators and law enforcement, where disclosure is required or authorised by law; and
  • other parties where we have your consent, or where disclosure is necessary to protect the rights, property or safety of Ralle, our users or others.

We do not sell personal information.

7. Service providers and sub-processors

We engage third parties to help us deliver the Services, including cloud hosting and communications providers. Where they process personal information on our behalf, we engage them under a written agreement imposing data protection obligations that meet the requirements of applicable data protection law, and we remain responsible for their performance.

The sub-processors we engage in providing our platform to customers, together with the categories of information they handle and where they process it, are listed in our sub-processor register at ralle.co/sub-processors. That register is maintained and updated as our sub-processors change.

8. Storage and international transfers

Ralle is an Australian company. Our core platform is hosted in Australia, in Microsoft Azure and Google Cloud data centres located in Australian regions, and authorised Ralle personnel may access platform data from Australia.

Where we act as a controller, we also use service providers located outside Australia, including in the United States, for our customer relationship management, website hosting, website analytics, embedded website content, electronic signature and internal business systems. These are separate from the sub-processors listed in our sub-processor register, which covers only the providers we engage to deliver our platform to customers.

If you are in the United Kingdom or the European Economic Area, this means your personal information will be handled outside your country. Australia is not currently the subject of adequacy regulations made by the United Kingdom, and is not the subject of an adequacy decision by the European Commission.

Where you provide information to us directly

Where you provide personal information to us directly, for example by using our Websites or contacting us, we receive that information in Australia. We protect it in accordance with this Privacy Policy, the Australian Privacy Act and, where it applies to us, the UK GDPR and EU GDPR.

Where information is transferred to us by a customer

Where an organisation using our platform transfers personal information to us from the United Kingdom or the EEA, that transfer is governed by the transfer mechanism set out in our agreement with that organisation. For United Kingdom customers we use the International Data Transfer Agreement issued by the Information Commissioner’s Office. Details are available from that organisation or from us on request.

9. Retention

We keep personal information only for as long as we need it for the purposes described in this Policy, or for as long as the law requires. Where we act as a controller, our retention periods are:

Where we act as a processor, retention of member and participant information is determined by the organisation that engaged us, and is set out in our agreement with that organisation.

10. Your rights

You have the right to ask us to give you access to the personal information we hold about you, and to correct it if it is inaccurate or incomplete. These rights apply wherever you are located.

If the UK GDPR or EU GDPR applies to our handling of your personal information, you also have the right to:

  • ask us to erase your personal information in certain circumstances;
  • ask us to restrict how we use your personal information in certain circumstances;
  • object to our use of your personal information where we rely on legitimate interests, and to object at any time to its use for direct marketing;
  • receive certain personal information you have given us in a portable format, or ask us to transmit it to another organisation; and
  • withdraw your consent at any time, where we rely on consent. Withdrawing consent does not affect anything we did before you withdrew it.

To exercise any of these rights, contact our Privacy Officer using the details in section 14. We may ask you to verify your identity before we act on a request. We will respond within the time required by the applicable law, and we will not charge a fee unless your request is manifestly unfounded or excessive.

If we decline a request, we will tell you why in writing and explain how you can complain.

If your request relates to information we hold as a processor on behalf of a club, association, charity or venue, we will direct you to that organisation and assist it in responding to you.

11. Direct marketing

If at any time you do not wish to receive marketing communications from us, use the unsubscribe link in any message or contact our Privacy Officer. We will action your request and keep the minimum information necessary to make sure we do not contact you again.

Where we send marketing by electronic means we comply with the Spam Act 2003 in Australia and, where applicable, the Privacy and Electronic Communications Regulations in the United Kingdom.

12. Websites, cookies and security

Each time you visit our Websites, our web servers may collect your IP address, the date, time and duration of your visit, and the pages and documents accessed. We use this information to improve our Websites and our service.

Cookies

Our Websites use cookies, which are small text files placed on your device. We use three categories.

Strictly necessary cookies. These are needed to deliver our Websites, keep them secure and remember your cookie preferences. We do not need your consent to set these cookies.

Analytics cookies. We use Google Analytics to understand how our Websites are used so that we can improve them. These cookies record information such as the pages you visit, how long you spend on them and how you arrived at our site. We set these cookies only where you have given your consent.

Embedded third-party content cookies. Some pages include content provided by others, such as our contact form, which is hosted by ClickUp. That content may set its own cookies. We do not load it unless you have given your consent. Where you have not, we tell you what the content is and give you the option to load it.

Managing your choices. When you first visit our Websites you can accept or reject each category other than strictly necessary cookies. You can change your choices at any time using the Cookie Settings control, which is available on every page. We remember your choices for 12 months, or until you clear your browser data, after which we will ask again.

Most browsers accept cookies by default. You can configure your browser to reject them, though you may not be able to make full use of our Websites if you do.

Our Websites may contain links to third-party websites. If you follow those links, the operators of those sites may collect information about you. We are not responsible for their privacy practices, and you should review their own privacy notices.

We take reasonable technical and organisational measures to protect personal information against loss, misuse, unauthorised access, disclosure and alteration, consistent with recognised industry standards. No method of transmission over the internet is completely secure, and we cannot guarantee the security of information transmitted to us online.

13. Payment information

Where payment functionality is enabled, card details are captured directly by the relevant payment provider through its own hosted payment page. Ralle does not receive, process or store full payment card numbers.

14. How to contact us and how to complain

If you have any questions about this Privacy Policy or about how we handle your personal information, or if you wish to exercise any of your rights, please contact our Privacy Officer:

The Privacy Officer
Ralle Pty Ltd
Level 18, 324 Queen Street, Brisbane QLD 4000, Australia
support@ralle.co

Please include your full name and contact details so that we can respond.

We will acknowledge your complaint and tell you if we need more information from you. We aim to resolve complaints quickly, and will keep you informed of progress and give you an outcome without undue delay. If a complaint is taking longer than expected, we will tell you what is happening and when you can expect a response.

If you are not satisfied with our response

In Australia, you may complain to the Office of the Australian Information Commissioner by calling 1300 363 992, online at oaic.gov.au, or by writing to the Office of the Australian Information Commissioner, GPO Box 5288, Sydney NSW 2001.

In the United Kingdom, you may complain to the Information Commissioner’s Office by calling 0303 123 1113, online at ico.org.uk, or by writing to the Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF.

In the European Economic Area, you may complain to the supervisory authority in the country where you live or work, or where you consider the issue arose.

We would prefer to hear from you first so that we have the opportunity to put things right.

15. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. We will publish the current version on our Websites and update the effective date above. Where a change is material, we will give reasonable notice before it takes effect. We recommend that you review this Privacy Policy periodically.

The current version of this Privacy Policy is available at https://www.ralle.co/privacy-policy.html.